Design, Implementation, and Evolution of an ISMS
Initial Situation: According to the requirements, an ISMS based on ISO 27001 had to be developed within the client organization and implemented in approximately 170 organizational units for over 200 IT applications within 24 months. Between 2024 and 2025, around 218 prioritized IT applications were integrated, and maturity level 3 of the group’s internal capability model was achieved.
Problem: At the outset, the maturity level of procedural, organizational, and technological governance requirements was low, and a systematic implementation concept was lacking. After the initial roll-out, an additional 250 IT applications were not yet integrated, while regulatory requirements and IS risks continued to rise, demanding high management attention.
Need: A systematic implementation plan, strategic and operational support for the introduction and further development, and the integration of an additional 78 applications into the ISMS of the group management were required to further enhance cyber defense capabilities.
Recording of client-specific requirements
Development, presentation, coordination, and approval of a systematic approach model for ISMS implementation
Determination of required personnel and budgetary resources, and support for the internal approval process
Support in developing procedural, organizational, and technological requirements, and creating an IS policy
Support in developing suitable competence formats for application owners
Support for approximately 170 organizational units in implementing requirements at operational and strategic levels
A time-based and content-driven roll-out plan, including resource estimation, has been developed, coordinated, and approved
Governance requirements have been developed and are bindingly anchored within group management
Competence formats have been developed, introduced, and are continuously being refined
ISMS requirements are being successively implemented in the organizational units according to the roll-out plan
The maturity level of the ISMS is demonstrably and continuously improving
Required management levels and committees are involved
"Such rapid progress in the development and implementation of the ISMS would not have been possible without the consulting firm."
This project is relevant for corporate groups and conglomerates that need to establish an ISMS based on ISO 27001 group-wide and expand it to other applications after an initial roll-out. The approach is particularly relevant for many decentralized organizational units, tight deadlines, low governance maturity, increasing regulatory pressure, and high management attention. It combines conception, governance, resource and competence building with strategic and operational roll-out control.